Authentication

IntraPod uses authenticated sessions and server-resolved identity boundaries when authentication is enabled.

Organization isolation

Authenticated business data is scoped to the active organization on the server; browser-supplied tenant context is not authoritative.

Role-based permissions

Sensitive operations require established organization roles in addition to an authenticated session.

Encrypted connector credentials

Connector credentials are encrypted with authenticated context and are excluded from browser responses and application logs.

Origin and CSRF protection

Unsafe authenticated browser operations require an exact allowed Origin and the current session CSRF token.

Secure AI boundaries

The Support Assistant is grounded in approved documentation, receives no tenant business records, and is protected by bounded, fail-closed usage controls when enabled.

Readiness

Designed to support SOC 2 readiness.

Security controls and architecture can contribute to future audit readiness. IntraPod does not claim SOC 2 certification. Any future certification statement will require current, independently supported evidence.

Contact IntraPod